| Posted | Nick | Remark | |
|---|---|---|---|
| #openstack-nova - 2019-10-18 | |||
| 21:54:17 | efried | or is that completely the responsibility of the admin? | |
| 22:00:13 | sean-k-mooney | efried: i think its up to the admin/installer | |
| 22:01:06 | sean-k-mooney | e.g. we dont check that the config is 600 or 660 as far as i am aware | |
| 22:01:22 | efried | so if /etc/nova and contents were 5777 and owned by $random we would truck happily along? | |
| 22:01:31 | mriedem | gmann: melwitt: a couple of questions in the host_status_unknown patch - mostly for gmann about policy rule naming and the docs on the policy rule since 2.75+ https://review.opendev.org/#/c/679181/ | |
| 22:01:48 | sean-k-mooney | efried: i think so | |
| 22:02:09 | efried | o...kay. | |
| 22:02:24 | sean-k-mooney | nova does not create the file and we never write to it | |
| 22:02:45 | mriedem | efried: likely a question for bnemec | |
| 22:02:48 | sean-k-mooney | so its really up to the install to make sure that files with password in them are not world readable | |
| 22:03:29 | mriedem | i thought there was some talk of some how vaultifying that stuff but i might be dreaming that up | |
| 22:03:30 | efried | sean-k-mooney: well, that and if they're writable in any way a malicious user could make nova do horrible things to the system | |
| 22:03:44 | efried | mriedem: I think sdk does something like that. | |
| 22:03:49 | efried | or at least supports it. | |
| 22:03:57 | efried | for clouds.yaml | |
| 22:04:02 | efried | mordred: ^ | |
| 22:04:11 | efried | not that that's relevant here | |
| 22:04:39 | efried | I'll ML this sucker. | |
| 22:04:40 | sean-k-mooney | efried: i mean programs like ssh refuse to work if you dont set the right permisions in your ssh .config or key | |
| 22:04:45 | sean-k-mooney | so its not unresonable | |
| 22:04:59 | mordred | aroo? | |
| 22:05:03 | efried | right, swhat I'm sayin, it wouldn't be unreasonable for oslo and/or nova to enforce something like that. | |
| 22:05:27 | efried | but that doesn't mean we do | |
| 22:05:30 | mordred | oh - yeah - so - sdk supports clouds.yaml being split into clouds.yaml and secure.yaml | |
| 22:05:54 | mordred | we do not enforce that secure.yaml is actually secure - although I agree, it would be a reasonably sane thing to do | |
| 22:06:32 | efried | mordred: before I blast the ML, do you know off the top whether oslo.config does any such validation either? | |
| 22:06:35 | mriedem | https://specs.openstack.org/openstack/oslo-specs/specs/stein/secret-management-store.html ? | |
| 22:07:34 | sean-k-mooney | it looks like kolla atleast makes it 660 https://github.com/openstack/kolla-ansible/blob/master/ansible/roles/nova/tasks/config.yml#L57 | |
| 22:07:49 | mordred | efried: I do not know anything about oslo.config | |
| 22:07:57 | sean-k-mooney | they will be own by the kolla:kolla user and group by default | |
| 22:08:04 | sean-k-mooney | well on the host | |
| 22:08:11 | sean-k-mooney | they will be own by nova in the containers | |
| 22:08:15 | mriedem | efried: that spec looks pretty close but i don't see any code ever showed up for it | |
| 22:09:15 | efried | even if it was coded per the spec, though, it would only mean that you *could* secure your configs; it'd still be n/a for anyone using nova.conf | |
| 22:09:16 | sean-k-mooney | mriedem: i do think your recalection is right we did talk about vaultifing this at some point | |
| 22:10:03 | sean-k-mooney | im not sure it was that oslo spec specificaly but seam likely that was related | |
| 22:13:17 | mriedem | anywho, i'm going to drop now, have a good weekend o/ | |
| 22:13:22 | efried | o/ | |
| 22:13:31 | efried | drink lots of fluids. Suck on zinc. | |
| 22:13:46 | sean-k-mooney | o/ | |
| 22:14:05 | sean-k-mooney | efried: looks like kolla locks it down to 600 in the containers https://github.com/openstack/kolla-ansible/blob/master/ansible/roles/nova-cell/templates/nova-compute.json.j2#L8 | |
| 22:14:38 | efried | gtk | |
| 22:15:05 | sean-k-mooney | yep it means that at least implcitly there is nothing that requires the group to be able to read nova.conf | |
| 22:15:38 | sean-k-mooney | that makes sense however nothing out side of nova should read nova's config | |
| 22:17:33 | sean-k-mooney | mordred: by the way is there any reason not to use the cloud.yml vs the old rc files | |
| 22:17:58 | sean-k-mooney | i assume no but just said i woudl ask | |
| 22:18:00 | efried | you mean in nova? | |
| 22:18:01 | mordred | sean-k-mooney: you should never use old rc files they are evil and horrible | |
| 22:18:02 | efried | or in sdk? | |
| 22:18:13 | efried | oh, I don't know what an "old rc file" is, /me stfu | |
| 22:18:19 | sean-k-mooney | i mean when im runing the openstack cli | |
| 22:18:32 | mordred | efried: the files with env vars set in them | |
| 22:18:40 | sean-k-mooney | ya those | |
| 22:18:48 | sean-k-mooney | the openrc file that devstack has | |
| 22:18:55 | mordred | sean-k-mooney: yeah - definitely not - clouds.yaml is much betterer than env var files | |
| 22:19:07 | mordred | the only reason to keep those openrc files around are the legacy cli clients | |
| 22:19:30 | sean-k-mooney | right which im trying not to use anymore | |
| 22:19:52 | sean-k-mooney | we should file a bug with horizon to not default to the RC files | |
| 22:20:13 | mordred | ++ | |
| 22:20:17 | sean-k-mooney | you can download the cloud.yaml too but its not the default | |
| 22:21:01 | mordred | sean-k-mooney: I've also been meaning to write something like "openstack login" or similar that would let you slurp in a clouds.yaml you downloaded and maybe prompt you for your password and write it to secure.yaml or something like that | |
| 22:21:06 | mordred | but - you know - ENOTIME | |
| 22:21:38 | sean-k-mooney | i totaly dont just edit to add my password... | |
| 22:21:47 | sean-k-mooney | you know what i would love | |
| 22:21:56 | sean-k-mooney | a way to use keystoen with an ssh key | |
| 22:22:54 | sean-k-mooney | just let me upload my public key as an alternitive to a password then never ask me again. | |
| 22:23:47 | mordred | sean-k-mooney: ++ | |
| 22:24:11 | mordred | sean-k-mooney: I truly do not understand why this is not an actual option | |
| 22:24:23 | sean-k-mooney | time | |
| 22:24:42 | sean-k-mooney | also i dont think we ever asked the keystone folks | |
| 22:25:38 | mordred | I guess that's our fault | |
| 22:26:55 | sean-k-mooney | that would also be a way to secure the secure.yml i guess | |
| 22:27:56 | sean-k-mooney | anyway i shoudl actully finish up. enjoy the weekend o/ | |
| 22:29:35 | mordred | you too! | |
| 23:01:14 | efried | I'm outta here as well o/ | |
| #openstack-nova - 2019-10-19 | |||
| 01:18:11 | openstackgerrit | Dustin Cowles proposed openstack/nova master: Provider Config File: YAML file loading and schema validation https://review.opendev.org/673341 | |
| 01:18:11 | openstackgerrit | Dustin Cowles proposed openstack/nova master: Provider Config File: Function to further validate and retrieve configs https://review.opendev.org/676029 | |
| 01:18:12 | openstackgerrit | Dustin Cowles proposed openstack/nova master: Provider Config File: Merge provider configs to provider tree https://review.opendev.org/676522 | |
| 03:00:16 | openstackgerrit | wangfaxin proposed openstack/nova master: Fix review link. https://review.opendev.org/689612 | |
| 11:44:34 | openstackgerrit | Matthew Booth proposed openstack/nova master: Functional test for UnexpectedDeletingTaskStateError https://review.opendev.org/689278 | |
| 11:44:35 | openstackgerrit | Matthew Booth proposed openstack/nova master: Fix incorrect vm and task state after build failure race https://review.opendev.org/689388 | |
| 11:44:35 | openstackgerrit | Matthew Booth proposed openstack/nova master: Unplug VIFs as part of cleanup of networks https://review.opendev.org/663382 | |
| 17:48:53 | openstackgerrit | Merged openstack/python-novaclient master: Add images.GlanceManager.find_images() bulk query https://review.opendev.org/689537 | |
| 17:48:54 | openstackgerrit | Merged openstack/python-novaclient master: Add aggregate-cache-images command and client routines https://review.opendev.org/687141 | |
| 17:48:55 | openstackgerrit | Merged openstack/python-novaclient master: Add functional test for migration-list in v2.80 https://review.opendev.org/688635 | |
| #openstack-nova - 2019-10-20 | |||
| 00:12:24 | openstackgerrit | Merged openstack/nova master: Add support for cloud-init on LXC instances https://review.opendev.org/667976 | |
| 00:38:26 | openstackgerrit | Merged openstack/nova master: Remove dead reserve_volume compat code in _validate_bdm https://review.opendev.org/687427 | |
| 11:05:39 | openstackgerrit | Matthew Booth proposed openstack/nova master: Fix incorrect vm and task state after build failure race https://review.opendev.org/689388 | |
| 11:05:39 | openstackgerrit | Matthew Booth proposed openstack/nova master: Unplug VIFs as part of cleanup of networks https://review.opendev.org/663382 | |
| #openstack-nova - 2019-10-21 | |||
| 00:08:10 | openstackgerrit | Merged openstack/nova master: Remove Stein compute compat checks for volume type support https://review.opendev.org/687428 | |
| 06:58:10 | bauzas | good morning Nova | |
| 07:11:07 | gibi | bauzas: good morning! | |
| 07:11:21 | bauzas | :) | |
| 08:18:24 | lyarwood | remote: amqps://messaging-devops-broker02.web.prod.ext.phx2.redhat.com:5671: proton:io: recv: Connection refused | |
| 08:18:27 | lyarwood | argh sorry | |
| 08:23:14 | openstackgerrit | Balazs Gibizer proposed openstack/nova master: Fix ItemMatcher to avoid false positives https://review.opendev.org/689690 | |
| 08:33:58 | mdbooth | sean-k-mooney: You around, yet? Mind taking a look at Stephen's unplug vif patch and the functional test I wrote for it? Head: https://review.opendev.org/#/c/663382/12 Base: https://review.opendev.org/#/c/689186/2 | |
| 08:34:09 | mdbooth | 4 patches in total | |
| 08:34:29 | mdbooth | 2 bugs, unfortunately, as the functional test uncovered another one | |
| 11:18:59 | openstackgerrit | Merged openstack/nova master: Add PrepResizeAtDestTask https://review.opendev.org/627890 | |